CVE-2013-7061

medium

Description

Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.

References

https://plone.org/security/20131210/catalogue-exposure

http://www.openwall.com/lists/oss-security/2013/12/12/3

http://www.openwall.com/lists/oss-security/2013/12/10/15

Details

Source: Mitre, NVD

Published: 2014-05-02

Updated: 2014-06-30

Risk Information

CVSS v2

Base Score: 5.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

Severity: Medium

CVSS v3

Base Score: 5.4

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Severity: Medium